# Open Security Architecture (OSA) > Free, open security architecture patterns with NIST SP 800-53 Rev 5 control mappings and crosswalks to 87 compliance frameworks. Licence: CC BY-SA 4.0. ## Cheapest route A typical question: which pattern fits, which controls matter most, how they map to a framework, and what each one mitigates. 1. Choose the pattern from the list below, or search: `/api/v1/patterns?search=industrial`. 2. Ask for the join: `/api/v1/patterns/{id}/crosswalk?framework={ids}&emphasis=critical`. That is two requests. Sizes, with tokens estimated at 3.7 characters each: - This file: 15 KB, about 4,100 tokens. - Crosswalk for one pattern and one framework, critical controls only: 1 to 5 KB, about 300 to 1,400 tokens. - Pattern card, `/patterns/{id}.md`: median 3.7 KB, about 1,000 tokens. Scope, when to use it, controls by emphasis, what each critical control mitigates, and each threat with the controls that mitigate it. - Control card, `/controls/{id}.md`: median 1.7 KB. The patterns that use the control and its clauses in every framework. - Framework card, `/frameworks/{id}.md`: median 4.2 KB, largest 25 KB. Every clause OSA maps, with its controls. - Pattern as JSON, `/api/v1/patterns/{id}`: median 29 KB, about 7,700 tokens. - Pattern HTML page: 100 to 700 KB. It inlines the diagram, and it shows neither emphasis nor which threats a control mitigates. A pattern, control or framework page URL returns its card when the request's `Accept` header lists `text/markdown` ahead of `text/html`. The HTML pages, the cards and the API are generated from the same files in the data repository. Checking one against another adds no evidence. To check a mapping, read the framework's own text. ## For programs Use the JSON API. It needs no key. - [OpenAPI description](https://www.opensecurityarchitecture.org/openapi.yaml): 37 KB. The routes listed here are enough for the question above. - [Skill for coding agents](https://www.opensecurityarchitecture.org/skills/osa-security-patterns/SKILL.md): this route as a skill file, to install once. - One pattern with its controls and threats: `/api/v1/patterns/{id}`. Add `?fields=controls` or `?fields=threats` for one section. - One call for a pattern's controls, the threats each one mitigates, and its clauses in up to five frameworks: `/api/v1/patterns/{id}/crosswalk?framework=iec_62443,cra&emphasis=critical`. A control with no clause in a framework has an empty list and is named under `unmapped`: OSA records no mapping, which is not the same as no requirement. Where the framework has been compared with a published crosswalk, `unmapped_checked` says which of those have no clause there either. A control that SP 800-53 Rev 5 withdrew is marked `withdrawn`, with the controls it moved into and their clauses. - Keyword search: `/api/v1/patterns?search=remote+access`. Hits are ranked and carry a `score`. - One control with its framework clauses: `/api/v1/controls/{id}?fields=mappings` - One framework's control-to-clause mappings: `/api/v1/frameworks/{id}?fields=mappings&per_page=100` - IDs: patterns `SP-023`, controls `SC-07`, frameworks `iec_62443`. The lower-case hyphenated forms used in page URLs (`sp-023`, `sc-07`, `iec-62443`) are accepted too. - Unknown URLs return 404. Unknown API routes return a JSON error. - Limit without a key: 60 requests a minute per address, counted on `/api/v1/` only. This file, the cards and the pages are not limited. A 429 response carries `Retry-After`. A free key raises the limit: https://www.opensecurityarchitecture.org/api-keys/ - Source data as JSON files: https://github.com/opensecurityarchitecture/osa-data (`data/patterns`, `data/controls`, `data/framework-coverage`) - Version: this file was generated from that data on 2026-10-02. Each pattern carries its own release and modification date (`metadata.release`, `metadata.dateModified`). ## Patterns (53) Each line is `ID Title: scope`. Card: `/patterns/{id}.md`. Data: `/api/v1/patterns/{ID}`. Page: `/patterns/{id}/`. Not listed: SP-041 (superseded by SP-028), deprecated. - SP-001 Client Module: Reusable security module defining the standard control baseline for client endpoints including desktops, laptops, and workstations. - SP-002 Server Module: Reusable security module defining the standard control baseline for server systems including physical, virtual, and cloud-hosted instances. - SP-003 Privacy Mobile Device Pattern: Security architecture for protecting personally identifiable information (PII) on mobile devices, addressing data minimisation, encryption at rest, secure... - SP-004 SOA Publication and Location Pattern: Security architecture for protecting service registries and discovery mechanisms in service-oriented architectures. - SP-005 SOA Internal Service Usage Pattern: Security architecture for internal service-to-service communication in SOA and microservices environments. - SP-006 Wireless- Private Network Pattern: Security architecture for deploying and managing enterprise wireless networks as trusted extensions of the corporate LAN, covering WPA2/WPA3 encryption, 802.1X... - SP-007 Wireless- Public Hotspot Pattern: Security architecture for safely accessing corporate network resources from untrusted public wireless hotspots, using VPN tunnels, personal firewalls, strong... - SP-008 Public Web Server Pattern: Security architecture for internet-facing web applications, covering network segmentation, input validation, session management, TLS configuration, DDoS... - SP-009 Generic Pattern: Foundational reference pattern illustrating how NIST 800-53 control families map to a generic computing architecture of clients, servers, and networks. - SP-010 Identity Management Pattern: Security architecture for the lifecycle management of digital identities, covering identity provisioning, authentication, federation, authorisation, credential... - SP-011 Cloud Computing Pattern: Security architecture for organisations consuming or providing cloud services, addressing the shared responsibility model, data sovereignty, identity... - SP-012 Secure Software Development Lifecycle: End-to-end secure SDLC pattern covering threat modelling in design, secure coding standards, static and dynamic analysis, software composition analysis,... - SP-013 Data Security Pattern: Security architecture for classifying, protecting, and controlling data throughout its lifecycle. - SP-014 Awareness and Training Pattern: Security architecture for building and sustaining an effective security awareness and training program. - SP-015 Secure Remote Working: Comprehensive remote and hybrid working security pattern covering endpoint hardening, ZTNA and VPN architectures, BYOD and corporate device management, split... - SP-016 DMZ Module: Security architecture for designing and operating a demilitarized zone (DMZ) network segment. - SP-017 Secure Network Zone Module: Network segmentation and zone architecture module covering trust boundary design, micro-segmentation, firewall rule management, east-west traffic controls,... - SP-018 Information Security Management System: The Information Security Management System pattern is the catalogue umbrella under which every other OSA pattern operates. - SP-019 Secure Ad-Hoc File Exchange Pattern: Security architecture for enabling secure, business-driven file sharing with external partners without pre-established federation. - SP-020 Email Transport Layer Security (TLS) Pattern: Security architecture for protecting email communication at the infrastructure level using gateway-to-gateway TLS encryption. - SP-021 Realtime Collaboration Pattern: Security architecture for real-time collaboration platforms including video conferencing, screen sharing, instant messaging, and shared document editing. - SP-022 Board of Directors Room: Security architecture for protecting highly sensitive board-level communications and documents. - SP-023 Industrial Control Systems: Security architecture for protecting industrial control systems (ICS), SCADA, and operational technology environments. - SP-024 iPhone Pattern: Security architecture for managing iOS devices in enterprise environments. - SP-025 Advanced Monitoring and Detection: Security architecture for building advanced detection and response capabilities against sophisticated threats. - SP-026 PCI Full Environment: Security architecture for a fully PCI DSS compliant cardholder data environment. - SP-027 Secure LLM Usage: Security architecture for integrating large language models (LLMs) into enterprise environments. - SP-028 Secure DevOps Pipeline Pattern: Security architecture for CI/CD pipelines, DevSecOps practices, and software delivery automation. - SP-029 Zero Trust Architecture: Enterprise security architecture pattern that eliminates implicit trust, enforcing continuous verification of every user, device, and workload before granting... - SP-030 API Security: Comprehensive security pattern for protecting application programming interfaces across their full lifecycle. - SP-031 Security Monitoring and Response: End-to-end security operations pattern covering the full detection and response lifecycle: telemetry collection from endpoints, networks, and cloud;... - SP-032 Modern Authentication: Enterprise authentication architecture pattern covering directory services, federation, and token-based authentication using OIDC, OAuth 2.0, and JWT. - SP-033 Passkey Authentication: Deep-dive pattern for implementing phishing-resistant passwordless authentication using FIDO2 WebAuthn and passkeys. - SP-034 Cyber Resilience: Enterprise architecture pattern for designing systems that survive cyber attacks, maintain critical operations under degraded conditions, and recover rapidly. - SP-035 Offensive Security Testing: Governance and execution pattern for red teaming, blue teaming, purple teaming, and intelligence-led penetration testing (CBEST, TIBER-EU). - SP-036 Incident Response: End-to-end incident response pattern covering preparation, detection, triage, containment, eradication, recovery, and post-incident review. - SP-037 Privileged User Management: Comprehensive privileged access management pattern covering credential vaulting, just-in-time access, session recording, standing privilege elimination, and... - SP-038 Vulnerability Management and Patching: End-to-end vulnerability management pattern covering asset discovery, vulnerability scanning, risk-based prioritisation, patch management lifecycle, exception... - SP-039 Client-Side Encryption and Data Privacy: Pattern for implementing client-side encryption to protect sensitive user data before it reaches the server. - SP-040 Post-Quantum Cryptography and Quantum Readiness: Architecture pattern for migrating enterprise cryptographic infrastructure to post-quantum algorithms. - SP-042 Third Party Risk Management: Architecture pattern for managing security risk from third party vendors, service providers, and supply chain dependencies. - SP-043 Security Metrics and Measurement: Architecture pattern for designing, implementing, and governing a security metrics programme that drives decision-making, demonstrates programme effectiveness,... - SP-044 SaaS Identity Lifecycle Management: A security architecture pattern for managing the full identity lifecycle across SaaS applications -- from provisioning and role assignment through access... - SP-045 AI Governance and Responsible AI: A governance pattern for establishing and operating an AI management system (AIMS) across the enterprise. - SP-046 External Attack Surface Management: Comprehensive pattern for discovering, monitoring, and managing an organisation's internet-facing digital assets. - SP-047 Secure Agentic AI Frameworks: Enterprise security architecture for adopting agentic AI frameworks (LangChain, CrewAI, AutoGen, LangGraph, and similar orchestration platforms) safely at... - SP-048 Offensive AI and Deepfake Defence (draft): Security architecture for defending against AI used as a weapon against the enterprise — deepfake executive impersonation, AI-generated phishing and vishing at... - SP-049 AI in Security Operations (draft): Security architecture for the use of AI in defensive security operations — AI-augmented threat detection, AI-assisted incident triage and response,... - SP-050 Mobile Security Architecture (draft): Comprehensive mobile security architecture pattern covering certificate pinning, secure enclave usage, biometric authentication, mobile payment security (PCI... - SP-051 Tokenised Asset Security Architecture (draft): Security architecture for institutional tokenised asset platforms covering custody architecture (HSM, MPC, threshold signatures), smart contract security... - SP-052 Decentralised Identity & Verifiable Credentials (draft): Security architecture for decentralised identity (DID/SSI) systems covering W3C DID method selection and resolution, Verifiable Credential (VC) issuance and... - SP-053 Zero-Knowledge Proof Architecture (draft): Security architecture for zero-knowledge proof (ZKP) systems covering ZK-SNARK and ZK-STARK proof systems, trusted setup ceremony security, ZK-rollup... - SP-054 CBDC and Digital Currency Infrastructure (draft): Security architecture for central bank digital currency (CBDC) and digital currency infrastructure covering retail and wholesale CBDC models, dual-ledger... ## Controls (315) - [Control catalogue](https://www.opensecurityarchitecture.org/controls/): NIST SP 800-53 controls with guidance and framework clauses - Card for one control: `/controls/{id}.md`, for example `/controls/sc-07.md` ## Frameworks (87) - [Framework mappings](https://www.opensecurityarchitecture.org/frameworks/): clause-to-control coverage for each framework - Card for one framework: `/frameworks/{id}.md`, for example `/frameworks/iec_62443.md` - Framework ids: iso_27001_2022, iso_27002_2022, cobit_2019, cis_controls_v8, nist_csf_2, soc2_tsc, pci_dss_v4, csa_ccm_v4, csa_aicm, finos_ccc, iso_42001_2023, iec_62443, nis2, pra_op_resilience, mas_trm, apra_cps_234, asd_e8, bsi_grundschutz, anssi, finma_circular, osfi_b13, gdpr, dora, bio2, rbi_csf, fisc, lgpd_bcb, hkma_tme1, mlps_2, dnb_good_practice, cra, swift_cscf, sama_csf, nca_ecc, uae_ia, cbb_tm, qatar_nia, cbuae, cbe_csf, sa_js2, cbn_csf, bog_cisd, popia, bom_ctrm, iosco_cyber, bcbs_239, cpmi_pfmi, ffiec_is, nydfs_500, hipaa_sr, ecb_croe, eba_ict, sebi_cscrf, bot_cyber, cmmc_2, nerc_cip, nrc_73_54, tsa_psd, ieee_1686, ferc_cip, doe_c2m2, api_1164, awia, iaea_nss, pci_pts, fips_140, cbest, tiber_eu, pci_hsm, common_criteria, isae_3402, solvency_ii, lloyds_ms, naic_ds, pra_ss1_23, fca_sysc_13, hitrust_csf, fda_21_cfr_11, fda_cyber, iso_27799, nhs_dspt, owasp_masvs_v2, ccss_v9, mica, basel_sco60, bssc, sec_custody_digital ## About - [How to use OSA](https://www.opensecurityarchitecture.org/foundations/how-to-use/) - [Design principles](https://www.opensecurityarchitecture.org/foundations/design-principles/) - [Glossary](https://www.opensecurityarchitecture.org/definitions/glossary/) - [Licence](https://www.opensecurityarchitecture.org/about/license-terms/): Creative Commons Attribution-ShareAlike 4.0 - [GitHub](https://github.com/opensecurityarchitecture)